MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a383870010db689605e8aac2fd1a9ad284558ef9eccc6d07bdc9dbbc573480f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0a383870010db689605e8aac2fd1a9ad284558ef9eccc6d07bdc9dbbc573480f
SHA3-384 hash: 95789b1c403430a88f1a218e0028d20ca7f1e998eebb0631bf3ed0bac09bac30ca1f014c152f3cb185b44c1e27ff5fb3
SHA1 hash: 3240d9d15c6161272ac315b6acb38daa8c842e29
MD5 hash: 0bf3eb42e3645ccd8177a3f39b2672bb
humanhash: floor-twelve-north-kentucky
File name:SecuriteInfo.com.BehavesLike.Downloader.lr.18189
Download: download sample
Signature Dridex
File size:74'240 bytes
First seen:2020-05-11 16:11:30 UTC
Last seen:Never
File type:Excel file xls
MIME type:application/vnd.ms-excel
ssdeep 1536:hswh/Ck3hbdlylKsgqopeJBWhZFGkE+cL2NdAiT0wAqz:hswh/Ck3hbdlylKsgqopeJBWhZFGkE+B
Threatray 63 similar samples on MalwareBazaar
TLSH 27731333A78C5CD6D54692B7CDD996728322ED420A338EF72B50731F99799C08D8F226
Reporter SecuriteInfoCom
Tags:Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Document-Word.Trojan.Frs
Status:
Malicious
First seen:
2020-05-11 14:14:47 UTC
File Type:
Document
Extracted files:
28
AV detection:
19 of 31 (61.29%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Checks processor information in registry
Office loads VBA resources, possible macro or embedded object present
Program crash
Drops file in System32 directory
Process spawned suspicious child process
Blacklisted process makes network request
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments